PT-2026-65767 · Apache Airflow · Apache Airflow Fab Provider
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
apache-airflow-providers-fab versions prior to 3.7.3
Description
The FAB auth manager's Azure AD OAuth login process failed to verify the signature of the ID token by default, as the
verify signature variable was set to False. This allows an attacker to bypass authentication and log in as any user, including those with Admin privileges, by providing a forged or unsigned ID token (using alg:none) to the OAuth callback.Recommendations
Upgrade to version 3.7.3.
Exploit
Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Airflow Fab Provider